
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39581 is a SQL Injection vulnerability in the WP Sessions Time Monitoring Full Automatic WordPress plugin (also identified as activitytime) affecting versions 1.1.4 and earlier. It allows authenticated users with subscriber-level privileges to execute arbitrary SQL queries against the WordPress database. The vulnerability was reported by researcher hivesec on February 20, 2026, published by Patchstack on April 20, 2026, and disclosed to the NVD on June 16, 2026. It carries a CVSS v3.1 base score of 8.5 (High) (Patchstack, GitHub Advisory).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning the plugin fails to properly sanitize or parameterize user-supplied input before incorporating it into SQL queries. An attacker authenticated with only subscriber-level privileges — the lowest default WordPress role — can craft malicious requests that manipulate the underlying SQL command, enabling arbitrary database reads. No user interaction is required, and the attack is network-accessible with low complexity, making it straightforward to exploit. The scope is marked as "Changed," indicating the impact extends beyond the vulnerable component itself (Patchstack, GitHub Advisory).
Successful exploitation allows an authenticated subscriber to read arbitrary data from the WordPress database, potentially exposing user credentials (including hashed passwords), personal information, session tokens, and other confidential records stored across all database tables. The confidentiality impact is rated High, while integrity is unaffected and availability impact is Low. In a WordPress context, access to credential hashes could enable offline cracking and subsequent account takeover, including administrator accounts, facilitating full site compromise (Patchstack, GitHub Advisory).
wp-content/plugins/activitytime/readme.txt.wp_users (usernames and password hashes)./wp-admin/admin-ajax.php) or REST API routes associated with the activitytime plugin, containing SQL metacharacters (', ", --, UNION, SELECT, OR 1=1) in parameter values.wp_users, wp_usermeta, or other sensitive tables outside normal plugin operation.wp-content/plugins/activitytime/ if post-exploitation activity occurred.The vendor has released version 1.1.5 of the WP Sessions Time Monitoring Full Automatic plugin, which patches this vulnerability — all users should update immediately (Patchstack). As interim mitigations, site administrators should restrict subscriber role registration if not required, and deploy a Web Application Firewall (WAF) with SQL injection detection rules. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts without requiring an immediate plugin update. Database access logs should be monitored for anomalous query patterns.
Patchstack, which coordinated the disclosure, classified this vulnerability as high priority and noted that SQL injection vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites (Patchstack). The vulnerability was also referenced in Wordfence's weekly WordPress vulnerability report for the week of April 20–26, 2026, indicating broad coverage within the WordPress security community. No significant social media controversy or vendor dispute has been noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."